feat: keyring auto-unlock, Docker distribution, KDE Wayland, release … #1
Workflow file for this run
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| name: Release | |
| on: | |
| push: | |
| tags: | |
| - 'v*' | |
| jobs: | |
| # ── Android APK ───────────────────────────────────────────────────────────── | |
| build-android: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: actions/setup-java@v4 | |
| with: | |
| distribution: temurin | |
| java-version: '17' | |
| - uses: subosito/flutter-action@v2 | |
| with: | |
| channel: stable | |
| - name: Build APK | |
| working-directory: clients/app | |
| run: | | |
| flutter pub get | |
| flutter build apk --release --target-platform android-arm64 | |
| - name: Stage artifact | |
| run: | | |
| VERSION=$(grep '^version:' clients/app/pubspec.yaml | sed 's/version: //;s/+.*//') | |
| cp clients/app/build/app/outputs/flutter-apk/app-release.apk \ | |
| "LibreNotes-${VERSION}-android-arm64.apk" | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: android-apk | |
| path: LibreNotes-*-android-arm64.apk | |
| # ── Linux client (AppImage + tarball) ─────────────────────────────────────── | |
| build-linux-client: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - name: Install build dependencies | |
| run: | | |
| sudo apt-get update | |
| sudo apt-get install -y \ | |
| libgtk-3-dev libblkid-dev liblzma-dev libsecret-1-dev \ | |
| pkg-config ninja-build cmake clang | |
| - uses: subosito/flutter-action@v2 | |
| with: | |
| channel: stable | |
| - name: Build Linux artifacts | |
| run: bash scripts/package-linux.sh | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: linux-client | |
| path: | | |
| dist/LibreNotes-*.tar.gz | |
| dist/LibreNotes-*.AppImage | |
| # ── Server tarball ─────────────────────────────────────────────────────────── | |
| build-server: | |
| runs-on: ubuntu-latest | |
| steps: | |
| - uses: actions/checkout@v4 | |
| - uses: dart-lang/setup-dart@v1 | |
| with: | |
| sdk: stable | |
| - name: Install libsqlite3 | |
| run: sudo apt-get update && sudo apt-get install -y libsqlite3-dev | |
| - name: Build server tarball | |
| run: bash scripts/package-server.sh | |
| - uses: actions/upload-artifact@v4 | |
| with: | |
| name: server-tarball | |
| path: dist/librenotes-server-*.tar.gz | |
| # ── GitHub release ─────────────────────────────────────────────────────────── | |
| publish-release: | |
| needs: [build-android, build-linux-client, build-server] | |
| runs-on: ubuntu-latest | |
| permissions: | |
| contents: write | |
| steps: | |
| - uses: actions/download-artifact@v4 | |
| with: | |
| merge-multiple: true | |
| path: artifacts/ | |
| - uses: softprops/action-gh-release@v2 | |
| with: | |
| files: artifacts/** | |
| generate_release_notes: true | |
| # ── AUR (librenotes-bin) ───────────────────────────────────────────────────── | |
| # Runs in an Arch Linux container so makepkg is available. | |
| # Requires AUR_SSH_KEY secret: the private key whose public half is registered | |
| # on the AUR account that owns the librenotes-bin package. | |
| update-aur: | |
| needs: publish-release | |
| runs-on: ubuntu-latest | |
| container: | |
| image: archlinux:latest | |
| steps: | |
| - name: Install dependencies | |
| run: pacman -Sy --noconfirm git openssh curl base-devel | |
| - uses: actions/checkout@v4 | |
| - name: Set up SSH | |
| run: | | |
| mkdir -p ~/.ssh | |
| echo "${{ secrets.AUR_SSH_KEY }}" > ~/.ssh/id_rsa | |
| chmod 600 ~/.ssh/id_rsa | |
| ssh-keyscan aur.archlinux.org >> ~/.ssh/known_hosts | |
| - name: Update PKGBUILD and push to AUR | |
| run: | | |
| VERSION=$(grep '^version:' clients/app/pubspec.yaml | sed 's/version: //;s/+.*//') | |
| TARBALL_URL="https://github.com/${{ github.repository }}/releases/download/v${VERSION}/LibreNotes-${VERSION}-linux-x86_64.tar.gz" | |
| SHA256=$(curl -fsSL "$TARBALL_URL" | sha256sum | cut -d' ' -f1) | |
| git clone ssh://aur@aur.archlinux.org/librenotes-bin.git /tmp/aur | |
| # Update version and checksum in the PKGBUILD template from this repo | |
| sed \ | |
| -e "s/^pkgver=.*/pkgver=${VERSION}/" \ | |
| -e "s/^pkgrel=.*/pkgrel=1/" \ | |
| -e "s/^sha256sums_x86_64=.*/sha256sums_x86_64=('${SHA256}')/" \ | |
| aur/PKGBUILD > /tmp/aur/PKGBUILD | |
| # makepkg refuses to run as root — use a throwaway builder user | |
| useradd -m builder | |
| chown -R builder:builder /tmp/aur | |
| runuser -u builder -- bash -c "cd /tmp/aur && makepkg --printsrcinfo > .SRCINFO" | |
| git -C /tmp/aur config user.name "Piliii" | |
| git -C /tmp/aur config user.email "naifmohsenaziz@gmail.com" | |
| git -C /tmp/aur add PKGBUILD .SRCINFO | |
| git -C /tmp/aur commit -m "Update to v${VERSION}" | |
| git -C /tmp/aur push |